Define: Personal Data
Personal Data is any information relating to an identified or identifiable living individual, such as a name, email address, IP address, or ID number. In a contract, the term is typically defined by cross-reference to the applicable Data Protection Legislation, so its scope shifts with whatever law governs the agreement, rather than being spelled out independently in the clause itself.
Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI
What Personal Data Means in a Contract
When a contract states that Personal Data shall have the meaning given to it in the relevant Data Protection Legislation, it is deliberately outsourcing the definition to statute rather than fixing it in the document itself. This drafting choice means the parties are not inventing a bespoke category of protected information, they are adopting whatever the governing data protection law says counts as Personal Data at any given time. The practical effect is that the contractual obligations built around this term, such as confidentiality, security, and breach notification duties, automatically track legislative developments.
This approach is common because data protection law is detailed, technical, and subject to amendment. Rather than risk a contract falling out of step with the law, drafters use a floating definition that stays current. For businesses handling customer, employee, or supplier information, understanding that Personal Data is a legally defined term, not a colloquial one, is essential to correctly scoping data handling clauses.
How Personal Data Is Defined or Measured
Under most data protection regimes, Personal Data broadly means any information relating to an identified or identifiable natural person. This typically includes obvious identifiers like names and contact details, but also extends to online identifiers, location data, and factors specific to a person's physical, economic, cultural, or social identity. Identifiability is the key test, if a person can be singled out directly or indirectly from the data, alone or combined with other information, it is likely to qualify.
Because the definition is drawn from legislation rather than the contract, its precise boundaries depend on the law governing the contract. Some regimes distinguish between ordinary Personal Data and special or sensitive categories, such as health or biometric information, which attract stricter handling requirements. A well drafted agreement should acknowledge this layering, especially where the parties expect to process both standard and sensitive data.
- Direct identifiers: names, email addresses, national ID numbers
- Indirect identifiers: device IDs, cookies, IP addresses
- Sensitive categories: health records, biometric data, in some regimes criminal history
Where Personal Data Appears in Agreements
The term surfaces most often in clauses dealing with confidentiality, data processing, security obligations, and breach response. It is central to any Data Processing Agreement or Data Protection Addendum, where the parties allocate responsibilities for how Personal Data is collected, stored, and transferred. It also appears in privacy notices, employment contracts, and vendor agreements wherever one party will have access to information about the other's customers, employees, or users.
Industries that routinely handle large volumes of individual level information, such as Healthcare, Finance, and Retail, tend to build especially detailed Personal Data provisions into their contracts, reflecting heightened regulatory scrutiny. Cross-border arrangements often layer in a Data Transfer Agreement to address international movement of such data.
Why the Exact Wording Matters
Because the definition is borrowed from external legislation, the precise wording of the incorporation clause matters more than it might first appear. Ambiguity about which legislation applies, particularly in contracts spanning multiple jurisdictions, can create uncertainty about whether certain information is even covered. If the contract fails to specify a governing framework or update mechanism, disputes can arise over whether newly emerging categories of data, like inferred profiling data, fall within scope.
Vague drafting also affects downstream obligations. If Personal Data is defined too narrowly, security and breach notification duties may not extend to information that regulators or courts would treat as protected. Conversely, an overly broad reading can impose unnecessary compliance burdens. Getting the definition right is foundational to every other data related clause in the agreement.
Drafting Considerations
Drafters should confirm that the reference to Data Protection Legislation is clearly defined elsewhere in the contract, ideally naming the specific laws or a mechanism for identifying the governing framework as it evolves. It is also worth considering whether the contract needs to distinguish ordinary Personal Data from special categories, since these often trigger different obligations.
Parties negotiating data-heavy agreements should review related documents together, such as a Data Sharing Agreement or supporting policies, to ensure consistent terminology throughout. For further background on how these definitions have evolved, see this overview of past, present and future data protection legislation.
Finally, contracts should anticipate legislative change by including a mechanism for updating obligations if the definition of Personal Data shifts, rather than leaving the parties to renegotiate every time the underlying law is amended.
Relevant Circumstances
- When information identifying a living individual is being processed under a contract
- If GDPR or other data-protection legislation governs how data is handled
- Where data-processing terms need to flow down across the supply chain